CVE-2026-32906: OpenClaw < 2026.5.12 - Privilege Escalation in Slack Plugin Approvals via Exec Approver Gate
OpenClaw before 2026.5.12 contains a privilege escalation vulnerability in Slack plugin approvals that allows exec-authorized users to resolve plugin approvals through the exec approver gate. Attackers with limited exec approval permissions can bypass intended approval splits to approve plugin actions outside operator configuration.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClawto a version that resolves this vulnerability.Fixed in 2026.5.12
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32906?
The severity of CVE-2026-32906 is classified as low with a score of 2.3.
How do I fix CVE-2026-32906?
To fix CVE-2026-32906, update OpenClaw to version 2026.5.12 or later.
What type of vulnerability is CVE-2026-32906?
CVE-2026-32906 is a privilege escalation vulnerability.
Which software is affected by CVE-2026-32906?
The affected software is OpenClaw prior to version 2026.5.12.
What can attackers accomplish through CVE-2026-32906?
Attackers can bypass intended approval splits to resolve plugin approvals using limited exec approval permissions.